A Docker-cache path traversal in Artifactory rattles the registry every team pulls from
CVE-2026-66384, a path traversal in Artifactory’s Docker cache, lets an authenticated user write outside the intended directory and joined CISA’s KEV catalog on 27 August 2026. Upgrade your self-hosted instance to 7.146.35 or 7.161.16 and restrict remote repository creation.